PT-2026-92355 · Google · Pixel 11+7
CVE-2026-58704
·
Published
2026-09-15
·
Updated
2026-10-03
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Google Pixel versions 6 through 11, Pixel Tablet, and Pixel Fold (affected versions prior to security patch level 2026-09-05)
Description
A high-severity logic error in the Cellular Modem component of Google Pixel devices allows for a permission bypass. This flaw enables a remote attacker located on an adjacent or proximal radio network to escalate privileges to elevated system or modem execution contexts. The issue is a zero-click flaw, meaning it requires no user interaction to exploit. It has been observed in limited, targeted real-world attacks, often associated with commercial spyware or state-aligned surveillance targeting high-value individuals. Technical exploitation occurs within baseband memory buffers and involves bypassing internal permission gates via the modem's inter-process communication (IPC) logic.
Recommendations
Update all Google Pixel hardware to security patch level 2026-09-05 or later.
As a temporary mitigation in high-threat environments, enable Airplane Mode and use trusted Wi-Fi networks to restrict proximal RF exposure.
For high-risk targets, consider enabling Android Advanced Protection or Lockdown Mode.
Fix
DoS
RCE
LPE
Improper Authorization
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pixel 10
Pixel 11
Pixel 6
Pixel 7
Pixel 8
Pixel 9
Pixel Fold
Pixel Tablet